Product
high
advisory
Remote Code Execution in SPIP SQLite Installations via CVE-2026-66738
1 rule 1 TTP 1 CVESPIP versions prior to 4.4.18 contain a code injection vulnerability in the navigation menu endpoint that allows authenticated editors to execute arbitrary OS commands on SQLite-backed installations.
SPIP
web-application
rce
authentication-bypass
1r
1t
1c
high
advisory
SPIP RCE Vulnerability in Nginx Configurations (CVE-2026-8430)
2 rules 1 TTP 1 CVESPIP versions prior to 4.4.14 contain a remote code execution vulnerability exploitable in certain Nginx configurations, allowing attackers to execute arbitrary code within the web server's context.
SPIP +1
vulnerability
rce
webserver
2r
1t
1c
critical
threat
CVE-2026-8429: SPIP Remote Code Execution Vulnerability
2 rules 1 TTP 1 CVESPIP versions prior to 4.4.14 contain a remote code execution vulnerability (CVE-2026-8429) in the private space, allowing attackers to execute arbitrary code in the context of the web server, bypassing SPIP security screen protections.
SPIP
cve-2026-8429
rce
2r
1t
1c